Back to search
CVE-2020-7656
Published: May 19, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
| Vendor | Product | Versions |
|---|---|---|
n/a | jquery | affected All versions prior to version 1.9.0 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now